ある組織がデータ侵害を発見し、その結果、PII が一般に公開されました。教訓のレビュー中に、委員会は外部報告の責任者とタイミング要件に関する矛盾を特定しました。報告の問題に対処するには、次のどのアクションが最適ですか。
正解:B
Researching federal laws, regulatory compliance requirements, and organizational policies to document specific reporting SLAs is the best action to address the reporting issue. Reporting SLAs are service level agreements that specify the time frame and the format for notifying the relevant authorities and the affected individuals of a data breach. Reporting SLAs may vary depending on the type and severity of the breach, the type and location of the data, the industry and jurisdiction of the organization, and the internal policies of the organization. By researching and documenting the reporting SLAs for different scenarios, the organization can ensure that it complies with the legal and ethical obligations of data breach notification, and avoid any penalties, fines, or lawsuits that may result from failing to report a breach in a timely and appropriate manner.